CVE-2026-28301: SolarWinds Observability Self-Hosted Open Redirect Vulnerability
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Observability Self-Hostedto a version that resolves this vulnerability.Fixed in 2026.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28301?
The severity of CVE-2026-28301 is medium, rated at 4.8.
What type of vulnerability is CVE-2026-28301?
CVE-2026-28301 is an open redirect vulnerability that allows an attacker to redirect a user to an unintended external site.
How do I fix CVE-2026-28301?
To fix CVE-2026-28301, SolarWinds recommends upgrading to SolarWinds Observability Self-Hosted version 2026.2 as soon as possible.
What software is affected by CVE-2026-28301?
CVE-2026-28301 affects SolarWinds Observability Self-Hosted software.
What are the potential impacts of CVE-2026-28301?
The potential impact of CVE-2026-28301 includes an attacker redirecting users to malicious websites.